XML Sitemap & Google News Security & Risk Analysis

wordpress.org/plugins/xml-sitemap-feed

Take control of your WordPress core XML Sitemap and add a Google News Sitemap.

100K active installs v5.7.2 PHP 5.6+ WP 4.4+ Updated Jan 28, 2026
google-newsnewsrobotssitemapxml
98
A · Safe
CVEs total1
Unpatched0
Last CVEMay 7, 2024
Safety Verdict

Is XML Sitemap & Google News Safe to Use in 2026?

Generally Safe

Score 98/100

XML Sitemap & Google News has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 7, 2024Updated 2mo ago
Risk Assessment

The plugin "xml-sitemap-feed" v5.7.2 exhibits a generally good security posture based on the static analysis. The complete absence of identified entry points like AJAX handlers, REST API routes, shortcodes, and cron events significantly reduces the potential attack surface. Furthermore, the code signals indicate a responsible approach to development, with a reasonable percentage of SQL queries using prepared statements and a majority of outputs being properly escaped. The presence of nonce and capability checks, although limited in number, also suggests some consideration for security. There were no critical or high-severity taint flows detected, which is a positive indicator.

However, the plugin's vulnerability history is a significant concern. A past high-severity vulnerability related to Remote File Inclusion (RFI) in 2024 is a serious red flag. While this specific vulnerability is listed as patched, the nature of RFI vulnerabilities indicates a potential for severe code execution. This history suggests that developers need to be particularly vigilant about input validation and file handling within the plugin. The fact that there are no currently unpatched vulnerabilities is positive, but the historical pattern warrants caution and a thorough review of how file operations and include/require statements are managed to prevent recurrence.

In conclusion, while the current static analysis of version 5.7.2 shows promising security practices, the historical RFI vulnerability cannot be overlooked. The plugin demonstrates strengths in limiting its attack surface and implementing some security best practices. The weakness lies in its past vulnerability, which necessitates ongoing scrutiny of its security implementation, particularly concerning file operations and any potential for code injection.

Key Concerns

  • Past high-severity RFI vulnerability
  • SQL queries not always using prepared statements (43% un-prepared)
  • Outputs not always properly escaped (23% un-escaped)
Vulnerabilities
1

XML Sitemap & Google News Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-4441high · 8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

XML Sitemap & Google News <= 5.4.8 - Unauthenticated Local File Inclusion

May 7, 2024 Patched in 5.4.9 (3d)
Code Analysis
Analyzed Mar 16, 2026

XML Sitemap & Google News Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
4 prepared
Unescaped Output
84
280 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

57% prepared7 total queries

Output Escaping

77% escaped364 total outputs
Attack Surface

XML Sitemap & Google News Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
filterrobots_txtinc\class-sitemap-plugin.php:54
actionxmlsf_nginx_helper_purge_urlsinc\functions-debugging.php:23
actionxmlsf_sitemap_loadedinc\functions-debugging.php:72
actionshutdowninc\functions-debugging.php:75
actionxmlsf_sitemap_news_loadedinc\functions-debugging.php:79
actionshutdowninc\functions-debugging.php:82
actionxmlsf_installinc\functions-debugging.php:86
actionxmlsf_upgradeinc\functions-debugging.php:94
actioninitupgrade.php:20
filterget_terms_argsviews\admin\field-news-categories.php:12
actionplugins_loadedxml-sitemap.php:65
filterrobots_txtxml-sitemap.php:66
actionxmlsf_sitemap_loadedxml-sitemap.php:67
actionxmlsf_news_sitemap_loadedxml-sitemap.php:68
actionadmin_menuxml-sitemap.php:71
actionadmin_initxml-sitemap.php:72
actionadmin_initxml-sitemap.php:73
actionadmin_initxml-sitemap.php:74
Maintenance & Trust

XML Sitemap & Google News Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version5.6
Downloads4.5M

Community Trust

Rating88/100
Number of ratings83
Active installs100K
Developer Profile

XML Sitemap & Google News Developer Profile

Rolf Allard van Hagen

8 plugins · 111K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
293 days
View full developer profile
Detection Fingerprints

How We Detect XML Sitemap & Google News

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xml-sitemap-feed/inc/admin/css/sitemap-admin.css/wp-content/plugins/xml-sitemap-feed/inc/admin/js/sitemap-admin.js
Script Paths
/wp-content/plugins/xml-sitemap-feed/inc/admin/js/sitemap-admin.js
Version Parameters
xml-sitemap-feed/inc/admin/css/sitemap-admin.css?ver=xml-sitemap-feed/inc/admin/js/sitemap-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
xmlsf-admin-settings-wrapxmlsf-nav-tab-wrapperxmlsf-nav-tabxmlsf-nav-tab-active
HTML Comments
XML Sitemap & Google News - General SettingsXML Sitemap & Google News - Sitemap SettingsXML Sitemap & Google News - Advanced SettingsXML Sitemap & Google News - Post Types Settings+8 more
Data Attributes
data-xmlsf-iddata-xmlsf-key
JS Globals
xmlsf_admin_params
FAQ

Frequently Asked Questions about XML Sitemap & Google News